Apple Patches CVE-2025-43300 Zero-Day in iOS, iPadOS, and macOS Exploited in Targeted Attacks

Apple Releases Security Updates to Fix Critical Zero-Day Vulnerability Exploited in Targeted Attacks
Photo: The Hacker News

Apple Releases Security Updates to Fix Critical Zero-Day Vulnerability Exploited in Targeted Attacks

Apple has rolled out important security updates addressing a critical zero-day vulnerability tracked as CVE-2025-43300, affecting iOS, iPadOS, and macOS. The flaw, residing in the ImageIO framework, could lead to memory corruption when processing a specially crafted image, making it exploitable for attacks. The vulnerability, which carries a CVSS score of 8.8, has reportedly been used in targeted attacks, potentially affecting high-profile individuals. Apple has enhanced bounds checking to mitigate this flaw, which was discovered internally. The issue has been patched in the following versions: iOS 18.6.2, iPadOS 18.6.2, macOS Ventura 13.7.8, macOS Sonoma 14.7.8, and macOS Sequoia 15.6.1. Although Apple has not disclosed the perpetrators or specific targets of the attack, it is highly likely that this vulnerability was part of sophisticated, highly targeted campaigns. This fix adds to the seven zero-day vulnerabilities Apple has addressed this year, which also include flaws in Safari and other core components. Users are strongly advised to update their devices to secure their systems against potential exploits.

Leave a Reply

Your email address will not be published. Required fields are marked *